Iranian state-linked threat group MuddyWater targeted governments, ministries, universities, telecommunications providers, and other organizations in Turkey, the Arabian Peninsula, Pakistan, Armenia, and nearby countries with evolving espionage malware campaigns. Researchers said the group delivered malicious Excel and Office documents through phishing, using macros and the Office exploit CVE-2017-0199 to launch multi-stage infections that dropped Windows Script Files, persistence components, and remote access tools including SloughRAT—also tracked as Canopy—along with additional Visual Basic and JavaScript implants.
The intrusion chains used compromised or attacker-controlled infrastructure, regional decoy themes tied to Tajikistan, Pakistan, and Kurdistan, and fallback behavior that sometimes redirected victims to benign sites when command-and-control failed. Cisco Talos and Clearsky reported that MuddyWater combined PowerShell, living-off-the-land binaries, DNS and HTTP command-and-control, token-tracking mechanisms, and staged payload retrieval to execute arbitrary commands on victim systems, underscoring a broader shift toward more flexible and advanced tradecraft aligned with Iranian intelligence objectives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos assessed with high confidence that activity targeting Turkey, Pakistan, Armenia, Jordan, and the Arabian Peninsula falls under the broader MuddyWater umbrella, but that MuddyWater is not a single monolithic actor. Talos described it instead as a conglomerate of multiple sub-groups sharing tactics, techniques, and procedures while focusing on different geographies.
A February 2022 CISA alert described a MuddyWater implant called Canopy. Cisco Talos later said its SloughRAT sample corresponds to that Canopy implant.
Cisco Talos attributed a new MuddyWater campaign targeting organizations in Turkey and the Arabian Peninsula to phishing-delivered malicious Excel documents that deployed SloughRAT/Canopy and additional Visual Basic and JavaScript implants. Talos also observed a partial attack sequence between December 2021 and January 2022 in which scheduled tasks retrieved VBS-based downloaders that executed payloads and exfiltrated command results.
Cisco Talos previously disclosed campaigns using similar Windows executables targeting Turkey in November 2021. The disclosure connected those operations with related MuddyWater activity in the region.
Cisco Talos said MuddyWater migrated from a homemade signaling-token system to CanaryTokens in September 2021 during attacks targeting Turkey with malicious Excel documents. Researchers assessed the token infrastructure was used to track successful infections.
Cisco Talos observed an EXE-based infection vector used by MuddyWater in August 2021. This marked another delivery method in the group's evolving campaigns.
Cisco Talos previously disclosed a MuddyWater campaign using similar Windows executables against Armenia in June 2021. The disclosure linked the activity to the same broader cluster of MuddyWater operations.
Cisco Talos observed a MuddyWater RAT deployment in April 2021. This was one of the infection chains Talos used to track the group's evolving tooling and delivery methods.
Cisco Talos observed a MuddyWater malicious-document campaign targeting entities in Pakistan in April 2021 using a court-case lure. The activity was part of the group's broader use of maldocs to deliver follow-on payloads.
Cisco Talos identified another MuddyWater script-based implant written in Visual Basic that was used during 2021 and 2022. The implant was capable of downloading and executing arbitrary commands on victim systems.
Clearsky reported that in June 2019 MuddyWater expanded its tradecraft by using malicious Office macros together with exploitation of CVE-2017-0199 in the same campaign. The activity targeted governmental and telecommunications entities and used regional decoy documents and compromised infrastructure.
Cisco Talos identified an additional MuddyWater implant written in JavaScript that was used across 2019 and 2020. The implant could download and run arbitrary commands on victim systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcethehackernews.com
Open sourceblog.talosintelligence.com
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceclearskysec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.